July 2026 Release Notes
Copy link

The Command Platform release notes include information about what’s new, which are updated monthly, and improvements and fixes, which are updated weekly.

ℹ️

Last updated: July 24, 2026

What’s New
Copy link

Learn about new features across the Command Platform. These features were released over the past month and are available now:

Risk
Copy link

Risk is the potential for loss or damage to your assets, operations, or reputation, due to vulnerabilities being exploited by a bad actor. Security teams must assess the risk level by evaluating the likelihood of a threat occurring and the impact that it would have if realized.

Manage Rapid7 Agents (Insight Agents) more efficiently
Copy link

We’ve updated the Rapid7 Agent Management experience to improve performance, consistency, and reliability. With this release, you can expect:

  • A faster, more responsive Agent Management experience.
  • More consistent interactions for common tasks, including actions, confirmations, and status messages.
  • Improved accuracy and consistency for agent data, metrics, and KPIs.
  • Streamlined workflows that make it easier to manage your agent deployment.

These improvements are powered by an updated backend architecture that provides a more reliable foundation for Agent Management today while supporting future enhancements as your environment grows.

Top of page

Focus remediation efforts with CVE publish date filtering
Copy link

In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub now includes a CVE Publish Date filter, allowing you to view and filter remediations based on when vulnerabilities were publicly disclosed. This helps you identify newly disclosed threats or long-standing vulnerabilities to prioritize remediation efforts effectively.

With this capability from Risk > Remediation Hub, you can:

  • Prioritize newly disclosed vulnerabilities using CVE publish date filters.
  • Support SLA-driven prioritization and backlog management.
  • Target remediation efforts more effectively based on threat timeline.
  • Align remediation workflows with organizational priorities and deadlines.

Top of page

Surface Microsoft Defender recommendations in Remediation Hub
Copy link

In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub now includes Microsoft Defender as a third-party remediation source. Customers using the latest Microsoft Defender connector for Attack Surface Management (Surface Command) can view Defender recommendations alongside remediation data from other sources, reducing context switching and helping your team prioritize the highest-impact fixes.

With this capability from Risk > Remediation Hub, you can:

  • View Microsoft Defender remediation recommendations directly in Remediation Hub.
  • Prioritize Defender findings alongside data from other remediation sources.
  • Manage remediation activity in a centralized workflow to reduce context switching.

Top of page

Generate and schedule Top Remediation reports from Remediation Hub
Copy link

In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub now includes reporting capabilities based on the Vulnerability Management (InsightVM) Top Remediations report. Generate high-level summary and detailed asset-level reports to prioritize actions, understand impacted assets, and share remediation insights across teams. Reports are available on-demand or on a schedule, in PDF, HTML, and CSV formats.

With this capability from Risk > Remediation Hub, you can:

  • Generate summary and asset-level reports on-demand or on a schedule.
  • Share reports in PDF, HTML, and CSV formats with security and IT teams.
  • Automatically deliver scheduled reports to asset owners to reduce manual follow-up.
  • Prioritize remediation across a hybrid environment with data from Vulnerability Management (InsightVM), Cloud Security (InsightCloudSec), and Attack Surface Management.

Top of page

Access Remediation Hub with Vulnerability Management (InsightVM) role-based permissions
Copy link

In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub is now available to all Vulnerability Management (InsightVM) users — no administrator privileges required. Role-based permissions ensure each user sees only the assets and remediations they are authorized to access, so asset owners can act on prioritized remediations for their assigned assets without relying on security team intervention.

With this capability from Risk > Remediation Hub, you can:

  • Access Remediation Hub as any Vulnerability Management (InsightVM) user.
  • View only the assets and remediations within your authorized scope.
  • See filters and metrics that automatically reflect your assigned asset data.

Top of page

Monitor remediation workflow activity in Remediation Hub
Copy link

In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub now surfaces workflow activity directly, giving security teams visibility into which workflows have run, execution counts, status, and related artifacts such as Jira tickets and ServiceNow incidents — without leaving the remediation workflow.

With this capability from Risk > Remediation Hub, you can:

  • View workflow execution history directly in Remediation Hub.
  • Monitor execution status, including successful, failed, and in-progress runs.
  • Access generated artifacts and workflow outputs in a centralized location.

Top of page


Threat
Copy link

A threat is any potential event or action that could exploit vulnerabilities in a system, causing harm to assets, data, or operations. Threats can originate from various sources, including malicious actors, natural disasters, or unintentional human errors.

Control infostealer alert scope with the external user toggle
Copy link

In Digital Risk Protection (Threat Command), you can now control whether infostealer alerts include external user matches — credentials associated with a customer-owned domain but without an organizational email address. This gives security teams more control over alert volume without sacrificing visibility into employee credential exposure.

With this capability from Intelligence > DRP Configurations > Customization (or Configurations > Customization in Digital Risk Protection (Threat Command)), you can:

  • Toggle external user alerting on or off to refine infostealer alert scope.
  • Reduce alert noise by disabling monitoring of external email matches while continuing to monitor internal organizational emails.
  • Apply the setting to future alerts only, with no impact on existing or previously resolved alerts.

Top of page

Updated admin group identification for cloud identity providers
Copy link

In SIEM (InsightIDR), how cloud admin users are identified has been updated. Admin users from cloud identity providers such as Okta and Entra ID are now determined by membership in a group with a recognized admin role applied, rather than by group name alone. This change improves the accuracy of admin user identification across cloud environments.

Top of page

Improved AI-powered query generation
Copy link

We’ve enhanced AI-powered Log Search query generation to better understand natural language prompts and reduce the manual effort required to build searches.

It can now:

  • Automatically interpret natural language time expressions, such as “yesterday” or “last 24 hours”, and apply the appropriate time range to the search.
  • Suggest relevant log sources and event source types based on the intent of your prompt.
  • Provide a more detailed AI Query Explanation that includes the selected time range and log sources, making it easier to understand how your prompt was translated into a search query.

These improvements help you create more accurate searches faster while providing greater transparency into how AI interprets your requests.

Top of page

Understand your assets faster with AI-generated summaries in Attack Surface Management
Copy link

The Asset Details view in Attack Surface Management now displays an AI-generated summary of the most relevant information about any asset, so you can quickly get up to speed on what matters most.

Access asset details from Attack Surface Management > Asset Details. With this capability, you can:

  • Get an instant overview of the key properties associated with any asset.
  • Investigate exposures and alerts with greater efficiency.
  • Make faster, more informed prioritization and remediation decisions.
  • Maintain a more consistent understanding of an asset across security workflows.
  • Provide feedback to the Rapid7 product team using the in-feature feedback option.

Read more about this feature in Explore assets and identities .

Top of page

Improvements and Fixes
Copy link

Keep track of improvements and fixes to core technology.

Application Security (InsightAppSec) and AppSpider
Copy link

No updates released at this time.

Top of page

Attack Surface Management (Surface Command)
Copy link

Version 1.0.930
Copy link

Software release date: July 22, 2026 | Release notes published: July 24, 2026

Improved:

  • Vector Command now requires service agreement acknowledgment before initiating testing.

Fixed:

  • Asset Correlation Information section now displays unique values without duplication.
  • Graphical Query Builder queries using dotted notation for referenced fields now return results consistent with explicit path traversal.

Connectors

The following connectors were updated in the Extension Library  since the previous release. Connector updates are published independently and may have been available before this release date.

New Connectors

  • Adaptive Security: Adaptive Security is a security awareness training platform that helps organizations protect against phishing and social engineering attacks. This connector imports users and groups from Adaptive Security into Surface Command.
  • Avigilon Alta: The Avigilon Alta (formerly Openpath) is a cloud-based physical access control solution for unified video and access control. This connector integrates Users, Access Groups, Access Control Units (ACUs), Readers, and Sites with the Rapid7 Platform.
  • Halcyon: Halcyon is an AI-powered anti-ransomware platform that detects, prevents, and recovers from ransomware attacks across managed endpoints. This connector imports Halcyon endpoint assets, tenant organizations, deployment groups, and policy groups into the Rapid7 Platform.

Updated Connectors

  • Cloudflare: Zero Trust device collection now ignores accounts where Zero Trust is not enabled, instead of failing the entire import.
  • CyberArk Endpoint Privilege Manager:
    • Migrated from deprecated GetComputers API to new Get Endpoints API.
    • Added CyberArkEpmComputer2 type with full unified model fulfillment.
  • Infoblox NIOS DDI: Page size updated to 100 for all functions.
  • Microsoft SQL:
    • Added a generic import feed with configurable queries.
    • Added mssql_query_config configuration type.
  • Mosyle MDM: Resolved correlation issue with MosyleDevice hostname.
  • SentinelOne Singularity: Strengthened unique key for SentinelOneSoftwareInstallation.
  • SonarQube: Fixed null values in SonarQubeIssue and SonarQubeRule exposure_type fields.
  • WatchGuard Endpoint Security: Resolved KeyError: WatchGuardDevice in get_managed_devices by handling pagination state.
  • Zscaler: Improve correlation on ZScalerZiaDevice.hostName value.

Version 1.0.929
Copy link

Software release date: July 15, 2026 | Release notes published: July 16, 2026

Improved:

  • Rapid7EASMDomain resolves_to_refs field now includes IP addresses and other domains that map to this domain.

Connectors

The following connectors were updated in the Extension Library  since the previous release. Connector updates are published independently and may have been available before this release date.

New Connectors

  • BlueCat Micetro: BlueCat Micetro is a multi-vendor DDI (DNS, DHCP, and IPAM) management platform that provides a unified interface for managing IP address space and DNS across heterogeneous network environments, supporting Microsoft, BIND, Cisco, Infoblox, and cloud DNS/DHCP services. This connector synchronizes IP address management data and DNS configuration from the Micetro REST API into the Command Platform, including network blocks and subnets, individual IP address allocations with assignment state and discovery metadata, authoritative DNS zones, and DNS resource records.
  • Paycom: Paycom is a comprehensive human capital management (HCM) software solution that helps businesses streamline their employment processes from recruitment to retirement. This connector integrates employee data with the Command Platform.
  • Scale Computing Fleet Manager: Scale Computing Fleet Manager is a cloud-hosted control plane for hyperconverged edge infrastructure running SC//HyperCore, enabling centralized management of distributed edge systems across multiple sites. This connector imports clusters and virtual machines from Scale Computing Fleet Manager into the Rapid7 Platform, enabling Surface Command to map distributed edge architectures and track the orchestration of edge infrastructure and its workloads.

Updated Connectors

  • Armis: Fixed null exposure_type on ArmisPolicy.
  • BloodHound Enterprise: Fixed null exposure_type on BloodHoundAttackType.
  • Check Point Harmony Endpoint:
    • Updated schema validation for CheckPointHarmonyEndpointAsset.
    • Updated dependencies.
  • Crowdstrike Falcon: Fixed invalid and null exposure_type on CrowdstrikeVulnerabilityExposure.
  • GCP Compute:
    • Improved guidance when no GcpProject IDs are available from GCP Core.
    • Clarified likely org-level permission dependency (roles/resourcemanager.organizationViewer).
  • GCP Core:
    • Improved test_connection diagnostics when no organizations are returned.
    • Preserved existing “No organizations found.” logging for no-org environments.
    • Added explicit guidance for missing roles/resourcemanager.organizationViewer.
  • Google Security Command Center:
    • Updated Security Center API to v2.
    • Improved error reporting in test connection.
  • Infoblox BloxOne Threat Defense: Fixed null exposure_type on InfobloxTdSecurityPolicy.
  • JumpCloud: Fixed JumpCloudDevice FQDN hostname correlation.
  • Microsoft Intune: Separated ingest import feed for devices and software.
  • OpenAI: Added OpenAIUsage type for completions usage data.
  • PostgreSQL:
    • Added generic import feed with configurable queries.
    • Added postgresql_query_config configuration type.
  • SentinelOne Singularity: Clarified required permissions documentation for Extended Security Posture Management.
  • Tenable Security Center: Fixed null exposure_type on TenableScPlugin2.
  • Tenable Vulnerability Management: Fixed null exposure_type on TenableIoPlugin2.
  • Wiz.io: Fixed null exposure_type on WizVulnerability.
  • Zimperium MTD:
    • Removed zScan scope.
    • Added import feed for CVEs and Threats.

Version 1.0.928
Copy link

Software release date: July 8, 2026 | Release notes published: July 13, 2026

Improved:

  • Connector update failures now include an Update Now button to facilitate immediate resolution.
  • The Connectors page now supports reviewing and applying multiple connector updates simultaneously.
  • Correlation Rules now display human-readable names and descriptions for automatic exclusion rules to improve clarity and usability.

Fixed:

  • Hostname and Domain filters now return matching records consistently across Network Services and Certificates pages.
  • The Test Connection button in Connector profile now displays a tooltip and disables when the test function is unavailable, preventing runtime errors.

Connectors

The following connectors were updated in the Extension Library  since the previous release. Connector updates are published independently and may have been available before this release date.

New Connectors

  • Nutanix Prism Central: Nutanix Prism Central is a centralized multi-cluster management plane that provides a single pane of glass for managing Nutanix infrastructure including virtual machines, hosts, clusters, networks, and images. This connector integrates with the Nutanix Prism Central v4 APIs to import infrastructure asset data into the Rapid7 Platform.

Updated Connectors

  • IGEL UMS: Fixed a schema validation error for the IgelUmsDevice type.
  • Microsoft Entra ID (formerly Azure AD): Added the AzureAdAppRoleAssignment type; app role assignments are now fetched as part of the applications feed.
  • SentinelOne Singularity: Added the new SentinelOneSoftwareInstallation type, linking per-agent installed software to SentinelOneSoftware.

Version 1.0.926
Copy link

Software release date: July 2, 2026 | Release notes published: July 6, 2026

Improved:

  • Executed queries now display 25 results instead of 10 for better readability.

Connectors

The following connectors were updated in the Extension Library  since the previous release. Connector updates are published independently and may have been available before this release date.

Updated Connectors

  • BigFix: Fixed a packaging error.
  • EZO AssetSonar:
    • Fixed schema type mismatches in EzoAssetSonarMember.
    • Added previously undeclared API fields to EzoAssetSonarAsset.
    • Pinned dependencies.
  • IGEL UMS: Fixed a schema validation error for IgelUmsDevice.
  • Kaseya VSA 10: Added Applied Policies enrichment with the M1051 (Update Software) mitigation.
  • Kaseya VSA 9: Added the M1051 (Update Software) mitigation to KaseyaVSA9Agent using the patch scan status API.
  • ManageEngine ServiceDesk Plus: Added schema validation for the ManageEngineServiceDeskUser type.
  • Matrix42 CMDB: Added Asset filter to only import assets with an operational status of Active.
  • Nozomi Vantage:
    • Added Nozomi certification headers (nn-app and nn-app-version) to all requests.
    • Added retry handling for API throttling responses (HTTP 429 and HTTP 503).
    • Improved vulnerability pagination and deduplication handling.
  • SolarWinds IT Asset Management: Fixed hostname correlation.

Top of page

Cloud Security (InsightCloudSec)
Copy link

Release availability for self-hosted users

Self-hosted users are able to download the latest version usually 4 business days after SaaS users are upgraded from the following locations:

  • Terraform deployments: Public S3 bucket . Modules can be updated with the terraform get -update command.
  • Amazon Elastic Container Repository (ECR) deployments: You can obtain the ECR build images for this version from the InsightCloudSec ECR Gallery 

Version 26.7.21
Copy link

Software release date: July 22, 2026 | Release notes published: July 22, 2026

New Features

  • Runtime Sensor Health Monitoring: Added real-time health status visibility for runtime sensors across Kubernetes clusters and container instances. The Kubernetes Clusters page and Resources Listing now display a Runtime Sensor status column (Healthy, Disconnected, or Degraded) for customers with a Runtime license, providing at-a-glance coverage and connectivity insights for deployed sensors.
  • Compliance Rule Mapping: Introduced a unified compliance mapping experience in the Insights Library with support for custom rule management on compliance packs.
    • Unified compliance mapping action: The separate Edit Metadata and Add to Custom Pack actions have been replaced by a single Map to Compliance Pack action, available as both a row action and a bulk action in the Insights Library. The new action handles pack membership and compliance rule mapping in one step.
    • Compliance rule mapping: When mapping an Insight to a compliance pack, you can now select one or more compliance rules from a cascading dropdown. If no rules are selected, only pack membership is added (equivalent to the previous Add to Custom Pack behavior).
    • Custom compliance rules on packs: Custom packs now support user-defined compliance rules (for example, Custom Control 1.3 or Internal Policy 2.1). Rules can be added, renamed, and deleted from the new Compliance Rules tab on the pack detail page. Renaming a rule preserves all existing Insight mappings.
    • Rule inheritance from base packs: Custom packs can inherit rules from base packs. Inherited rules are read-only and cannot be modified on the child pack.
    • Compliance Rules tab: The pack detail page now includes a Compliance Rules tab showing all rules associated with the pack, including user-defined rules and rules inherited from base packs. Rules can be filtered by source (Custom or Inherited).
    • New API endpoints: Available for managing compliance rules and mappings programmatically.
      • GET /pack/{pack_id}/insight-rule-mappings: Returns Insight-to-rule mappings for a specific pack
      • GET /packs-with-rules: Returns all packs with their available rules
      • POST /map-to-compliance-rule: Maps Insights to compliance rules within a pack
      • GET /pack/{pack_id}/rules: Lists all rules on a pack with Insight counts
      • POST /pack/{pack_id}/rules/create: Creates a custom rule on a pack
      • POST /pack/{pack_id}/rules/delete: Deletes a custom rule from a pack
      • POST /pack/{pack_id}/rules/rename: Renames a custom rule, preserving all existing mappings

New Compliance Packs

  • Added the CIS Microsoft Azure Storage Services Benchmark v1.0.0 compliance pack.

New Insights

  • Serverless Function Configured With Deprecated Runtime: Identifies AWS Lambda functions configured with a deprecated runtime. Maps to CIS AWS Compute Services Benchmark v1.1.0 control 12.11, CIS Controls v8.1.2 safeguard 7.4, NIST SP 800-53 Rev. 5, and CMMC Level 1 and CMMC Level 2.
  • Serverless Function With Admin Role: Identifies AWS Lambda functions configured with full administrative privileges. Maps to CIS AWS Compute Services Benchmark v1.1.0 control 12.9, NIST SP 800-53, NIST CSF v2.0, and CMMC.
  • Serverless Function With Public Access Policy: Identifies AWS Lambda functions that are publicly accessible via a resource-based policy. Maps to CIS AWS Compute Services Benchmark v1.1.0 control 12.6.
  • Web App With Load Balancer Using HTTP: Identifies Web Apps whose load balancer has a listener that uses HTTP.

New Query Filters

  • Serverless Function With Admin Role: Filters AWS Lambda functions whose execution role grants full administrative privileges.
  • Load Balancer Listener Frontend Protocols: Filters load balancers based on the frontend protocols their listeners use.
  • Load Balancer Listener Instance Protocols: Filters load balancers based on the instance protocols their listeners use.
  • Web App Load Balancer HTTP Configuration: Filters Web Apps whose load balancer has a listener that uses HTTP.

Updated Insights

  • Updated Instance Containing Sensitive Information In User Data (AWS) to include CIS-recommended remediation steps. Maps to CIS AWS Compute Services Benchmark v1.1.0 control 2.13.
  • Updated Instance not Managed by AWS Systems Manager to align with CIS v8 documentation, including updated remediation guidance. Added Feature Disabled and IAM tags for improved discoverability. Maps to CIS AWS Compute Services Benchmark v1.1.0 control 2.9.
  • Updated Instance Allows Use of Vulnerable IMDSv1 Protocol (AWS) to align with current style guidelines. Added compliance mappings for CIS Controls v8.1.2, NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 2, CMMC Level 1, and CMMC Level 2. Maps to CIS AWS Compute Services Benchmark v1.1.0 control 2.8.

Updated Query Filters

  • Renamed Load Balancer With HTTP Listener Not Redirecting To HTTPS to Load Balancer Comprehensive HTTP to HTTPS Redirection. Added a new All HTTP Listeners Redirect to HTTPS configuration option to identify load balancers where all HTTP listeners redirect requests to HTTPS.

Improved

  • Added a search input field to the Bot matched resources modal, allowing users to quickly locate a specific resource by name when a bot matches against a large number of resources.

Deprecations

  • Deprecated Query Filter: “Snapshot Accessible To Public”, renamed to “Snapshot Accessible To Public (Deprecated)”. Its functionality is now covered by the following two Query Filters:
    • “Snapshot Public Access”
    • “Database Snapshot Public Access” (new)
  • Deprecated Insight: “Snapshot Available to the Public” (Targeted deprecation in version 26.7, targeted removal in version 27.1). Its functionality can be replaced by the following two Insights:
    • “Snapshot Is Accessible to the Public”
    • “Database Snapshot Is Accessible to the Public” (new)
  • Compliance pack mappings have been updated to reference the replacement Insights.

Fixed

  • Fixed two issues affecting the IAM Principal Explorer. The Policy Stack link in the Resource Details > Permissions panel was navigating to an incorrect URL, resulting in an infinite loading state. Additionally, certain cloud roles caused the Principal Explorer to fail to render, displaying a Cannot destructure property 'id' error. Both navigation and rendering now work correctly.
  • Fixed a UI rendering issue where the navigation menu (accessed via the dot-grid icon in the top left) appeared behind the main frame due to a z-index conflict with the side navigation drawer.
  • Fixed an issue where the “Section” column was missing from Compliance Scorecard email subscription reports. Reports generated after June 1st were omitting this column; the field now populates correctly across all report exports.
  • Fixed an issue where Azure Function App Python runtime detection was using the legacy pythonVersion attribute instead of the current linuxFxVersion attribute used by Linux-based function apps, resulting in missing runtime version data for affected resources.
  • Fixed an issue where the Database Instances Without Automatic Backups insight was incorrectly flagging GCP read replica instances as non-compliant. Read replicas inherit backup configuration from their primary instance and are no longer evaluated against this insight.
  • Fixed Microsoft Teams bot notification messages not rendering at full width by correcting an Adaptive Card property key casing issue.

Version 26.7.7
Copy link

Software release date: July 9, 2026 | Release notes published: July 9, 2026

Improved

  • Added background job OrphanedCredentialCleanup that removes orphaned cloud credentials daily or on-demand. These orphaned credentials are unused by harvesting or other portions of the product.

New Insights

  • Ensure EC2 Auto Scaling Groups Propagate Tags to Launched Instances (Insight ID 2582) - Detects AWS Auto Scaling Groups where one or more tags are not configured to propagate to the EC2 instances they launch. This aligns with CIS AWS Compute Services Benchmark control 2.14.
    • Supported Clouds: AWS, AWS China, AWS GovCloud.
    • Compliance Pack Mappings: CIS Controls v8.1.2 (1.1), NIST 800-53 Rev 5 (CM-8, CM-8(1), PM-5), NIST 800-171 (3.4.1, 3.4.9, 3.12.4), NIST CSF 2.0 (ID.AM-01, ID.AM-07), CMMC Level 2 (CM.L2-3.4.1, CA.L2-3.12.4).
    • After re-harvesting, Auto Scaling Groups will show tag propagation compliance status. Groups with no tags are considered compliant. Groups not yet re-harvested will show as “unknown” and will not trigger findings.
  • Volume Not Marked for Deletion on Instance Termination (Insight ID 2591) - Identifies EBS Volumes attached to EC2 Instances that are not configured for automatic deletion upon Instance Termination, helping reduce orphaned resources and potential data exposure. Aligned with CIS AWS Compute Services Benchmark Control 2.12.
    • Compliance Pack Mappings: CIS Controls v8.1.2, NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 2, NIST CSF v2.0, and CMMC Level 2.
  • Instance Using Default Security Group - Identifies AWS EC2 Instances that are associated with a default security group rather than a specified custom security group.
  • Cloud Account Organization Without Tag Policy Enabled - Identifies management Cloud Accounts whose AWS Organization does not have Tag Policies enabled.

New Query Filters

  • Autoscaling Group Not Propagating Tags at Launch - Identifies Auto Scaling Groups where tags are not configured to propagate to launched instances.
    • Supported Clouds: AWS, AWS China, AWS GovCloud.
  • Cloud Account Organization Tag Policy Status - Identifies management Cloud Accounts based on Tag Policy enablement status at the Organization root.

New Compliance Pack

  • Added CIS Red Hat OpenShift Container Platform Benchmark v1.9.0 compliance pack.

Fixed

  • Fixed Cache Instance Auth Token Disabled Query Filter false positive. The filter now correctly inherits auth_token configuration.
  • Fixed Resource Associated With Public Subnet Query Filter to correctly detect ElastiCache public subnet associations in CloudFormation Template (CFT) scans.
  • Fixed an error that could cause IaC scan listing to fail with a database session error.
  • Fixed an issue where resources with exceptions were not showing on the misconfiguration UI and export.
  • Resolved intermittent Azure snapshot harvesting failures. Fixed an issue where the Azure snapshot harvester could intermittently fail with a NotImplementedError, preventing snapshot data from being collected during affected harvest runs.
    • The snapshot harvesting method is now defined directly on the Azure backend class, consistent with how all other cloud providers (AWS, GCP, AliCloud, Oracle) are implemented.
    • No changes to harvested data or behavior — runs that previously succeeded continue to work identically.

Top of page

Mimics Infrastructure as Code (IaC) Scanning Tool
Copy link

No updates released at this time.

Top of page

SIEM (InsightIDR)
Copy link

Improved:

  • Updated SentinelOne Third-Party Alert library to use inherited priority functionality.

Top of page

Vulnerability Management (InsightVM)
Copy link

Fixed

  • No longer executes files discovered on a target asset without verifying ownership during authenticated assessment, preventing a local privilege escalation (CVE-2026-14172). This fix is included in Scan Engine content version 1.1.3935.

Version 8.52.0
Copy link

Software release date: July 13, 2026 | Release notes published: July 13, 2026

Improved:

  • Improved Splunk Enterprise fingerprinting on Unix/Linux. Added a dedicated fingerprinter that detects Splunk Enterprise by querying the product directly for its version, replacing the previous OS package-based detection.This improves coverage for Splunk installations deployed outside the system package manager (e.g., tarball installs under /opt/splunk), resulting in more accurate software inventory and vulnerability assessment on affected hosts.
  • Added fingerprinting support for AI tools, MCP servers, and AI development skills, providing greater visibility into AI technologies deployed across your environment to help identify both authorized and unauthorized usage.
  • Added fingerprinting support for Microsoft Intune-managed applications. The scan engine can now detect and inventory software deployed and managed through Microsoft Intune (Microsoft Endpoint Manager), including Win32 apps, MSI line-of-business apps, and Microsoft Store for Business apps. This enhancement enables accurate software fingerprinting on Windows 10/11 endpoints enrolled in Intune, with proper version reporting that matches the Intune console. Duplicate software entries are reconciled when both a local installer and an Intune-managed installer are detected for the same application. Vulnerability assessments are automatically applied to discovered Intune-managed software where existing content coverage is available.

Fixed:

  • Resolved an issue where the scan engine incorrectly reported a Diffie-Hellman key size of 0 for TLS 1.3 services.
  • Fixed an issue where wildcard CVE searches in the General Search vulnerability tab could return incomplete or incorrect results. Wildcard prefix matching now behaves as expected.
  • Addressed an issue preventing reverse-paired Scan Engines from reconnecting automatically after a Security Console restart. Previously paired engines now reconnect as expected.
  • Fixed an issue that could cause PostgreSQL 15 major version migrations to fail during upgrade. Database migrations now complete successfully.

Version 8.51.0
Copy link

Software release date: July 7, 2026 | Release notes published: July 6, 2026

Improved:

  • Enhanced Oracle Access Management fingerprinting to improve patch version identification and reporting accuracy.
  • Improved scan logging for custom service names configuration issues, providing clearer messages when files are missing or cannot be parsed to simplify troubleshooting.
  • Strengthened the overall security posture of the Security Console by upgrading the bundled Axios library to the latest supported minor version.
  • Improved the performance and responsiveness of the Asset Search API, particularly for larger Security Console deployments.
  • Added built-in policy support for:
    • DISA STIG Microsoft SQL Server Database 2022 Benchmark V1R3
    • DISA STIG Microsoft SQL Server Instance 2022 Benchmark V1R4
  • Operating System Support: Added support for Microsoft Windows Server 2025 on the Vulnerability Management (InsightVM) Console, Nexpose Console, and Scan Engines.

Fixed:

  • Resolved an issue where the GET Scan Engine Sites API returned an incomplete value for scanTemplateName. The endpoint now returns the expected scan template name.
  • Fixed an issue where CSV vulnerability reports did not include tabular solution content, such as Windows Registry settings and configuration values. This information is now exported correctly.
  • Resolved an issue affecting Extensible Ingress when using a console proxy. Exposure Analytics traffic now correctly routes through the configured proxy, including authenticated proxies. A Security Console restart is required when using an authenticated proxy.

Top of page

Nexpose
Copy link

Fixed

  • No longer executes files discovered on a target asset without verifying ownership during authenticated assessment, preventing a local privilege escalation (CVE-2026-14172). This fix is included in Scan Engine content version 1.1.3935.

Nexpose Version 8.52.0
Copy link

Software release date: July 13, 2026 | Release notes published: July 13, 2026

Improved:

  • Improved Splunk Enterprise fingerprinting on Unix/Linux. Added a dedicated fingerprinter that detects Splunk Enterprise by querying the product directly for its version, replacing the previous OS package-based detection.This improves coverage for Splunk installations deployed outside the system package manager (e.g., tarball installs under /opt/splunk), resulting in more accurate software inventory and vulnerability assessment on affected hosts.
  • Added fingerprinting support for AI tools, MCP servers, and AI development skills, providing greater visibility into AI technologies deployed across your environment to help identify both authorized and unauthorized usage.
  • Added fingerprinting support for Microsoft Intune-managed applications. The scan engine can now detect and inventory software deployed and managed through Microsoft Intune (Microsoft Endpoint Manager), including Win32 apps, MSI line-of-business apps, and Microsoft Store for Business apps. This enhancement enables accurate software fingerprinting on Windows 10/11 endpoints enrolled in Intune, with proper version reporting that matches the Intune console. Duplicate software entries are reconciled when both a local installer and an Intune-managed installer are detected for the same application. Vulnerability assessments are automatically applied to discovered Intune-managed software where existing content coverage is available.

Fixed:

  • Resolved an issue where the scan engine incorrectly reported a Diffie-Hellman key size of 0 for TLS 1.3 services.
  • Fixed an issue where wildcard CVE searches in the General Search vulnerability tab could return incomplete or incorrect results. Wildcard prefix matching now behaves as expected.
  • Addressed an issue preventing reverse-paired Scan Engines from reconnecting automatically after a Security Console restart. Previously paired engines now reconnect as expected.
  • Fixed an issue that could cause PostgreSQL 15 major version migrations to fail during upgrade. Database migrations now complete successfully.

Nexpose Version 8.51.0
Copy link

Software release date: July 7, 2026 | Release notes published: July 6, 2026

Improved:

  • Enhanced Oracle Access Management fingerprinting to improve patch version identification and reporting accuracy.
  • Improved scan logging for custom service names configuration issues, providing clearer messages when files are missing or cannot be parsed to simplify troubleshooting.
  • Strengthened the overall security posture of the Security Console by upgrading the bundled Axios library to the latest supported minor version.
  • Improved the performance and responsiveness of the Asset Search API, particularly for larger Security Console deployments.
  • Added built-in policy support for:
    • DISA STIG Microsoft SQL Server Database 2022 Benchmark V1R3
    • DISA STIG Microsoft SQL Server Instance 2022 Benchmark V1R4
  • Operating System Support: Added support for Microsoft Windows Server 2025 on the Vulnerability Management (InsightVM) Console, Nexpose Console, and Scan Engines.

Fixed:

  • Resolved an issue where the GET Scan Engine Sites API returned an incomplete value for scanTemplateName. The endpoint now returns the expected scan template name.
  • Fixed an issue where CSV vulnerability reports did not include tabular solution content, such as Windows Registry settings and configuration values. This information is now exported correctly.

Top of page

Digital Risk Protection (Threat Command)
Copy link

Software release date: [June 19, 2026] | Release notes published: [July 6, 2026]

New:

  • You can now control whether infostealer alerts include external user matches — credentials associated with a customer-owned domain but without an organizational email address. The toggle is located under Configurations > Customization in Digital Risk Protection (Threat Command), or under Intelligence > DRP Configurations > Customization in the Command Platform. External user alerting is on by default, preserving existing behavior. When turned off, monitoring stops for external email matches while internal organizational email monitoring continues. This setting applies to future alerts only and has no effect on existing or previously resolved alerts.

Top of page

Rapid7 Agent (Insight Agent)
Copy link

Version 4.1.1 (Unchanged from previous release version)
Copy link

Fixed:

  • No longer executes files discovered on a target asset without verifying ownership during authenticated assessment, preventing a local privilege escalation (CVE-2026-14172). This fix is included in content component version 0.0.245.0.

Resolved an issue in a third-party Go library that prevented some Rapid7 Agent (Insight Agent) capabilities from working as intended on devices with Apple M5 Pro and M5 Max chipsets. The following capabilities are now restored on affected devices:

  • Endpoint Protection and Ransomware Prevention
  • Agent-based Policy
  • Hosted Velociraptor
  • On-demand vulnerability scans

If Command Platform (Insight Platform)-managed agent updates are enabled, the Rapid7 Agent (Insight Agent) will automatically update the Endpoint Broker, Agent Core, and Hosted Velociraptor components. For more information, see Data collected by the Rapid7 Agent (Insight Agent)  and Command Platform (Insight Platform)-managed agent updates .

Top of page

Next-Generation Antivirus
Copy link

No updates released at this time.

Top of page

Ransomware Prevention
Copy link

No updates released at this time.

Top of page

Velociraptor
Copy link

Version 0.74.4.27
Copy link

Software release date: [July 8, 2026] | Release notes published: [July 8, 2026]

Fixed:

Resolved an issue in a third-party Go library that prevented the Rapid7 Velociraptor client from working as intended on devices with Apple M5 Pro and M5 Max chipsets. For more information, see the Rapid7 Agent Release Notes.

Top of page

Automation (InsightConnect)
Copy link

No updates released at this time.

Top of page

Rapid7 Network Sensor (Insight Network Sensor)
Copy link

Version 2.1.0.1
Copy link

Software release date: July 7, 2026 | Release notes published: July 16, 2026

Improved:

  • Suricata received a major version upgrade from 7.0.15 to 8.0.5.
  • Support for the HL7 protocol, common in healthcare environments, has been overhauled to improve detection and reduce false positives.
  • Overhauled Zoom protocol support to improve detection accuracy, reduce false positives, and more accurately identify client and server roles.
  • Enhanced telemetry for ambiguous network traffic that matches multiple protocols. These improvements provide better visibility into protocol identification and support future enhancements to protocol recognition.

Fixed:

  • Fixed issues in SMTP direction finding to improve identification of SMTP servers.
  • Fixed false-negative issues affecting NNTP, FTP, SMTP, and POP3 protocol detection.
  • Fixed issues in Kerberos (krb5) protocol detection to improve Kerberos traffic detection.
  • Fixed an issue in the NetBIOS datagram protocol decoder to improve NetBIOS traffic detection.

New Protocols:

  • VNC: The sensor now detects the Virtual Network Computing (VNC) protocol, which is used for remote desktop access and control. This is an important protocol to detect as there is a potential security risk if there are unauthorized VNC servers running on the network, especially on unusual ports.
  • WCF (Windows Communication Foundation): The sensor now detects the WCF protocol, which is used by Microsoft applications for inter-process communication.
  • Meraki Cloud Protocol: The sensor now detects the Meraki Cloud Protocol, which is used by Cisco Meraki devices for cloud management and communication. This decoder was the result of AI-assisted protocol reverse-engineering.
  • Centrak Real-Time Location System (RTLS): The sensor now detects the Centrak RTLS protocol, which is used for tracking and managing assets in healthcare and other industries. This decoder was the result of AI-assisted protocol reverse-engineering.
  • JetDirect (PJL): The sensor now detects the JetDirect Printer Job Language (PJL) protocol, which is used by HP printers for job control and status reporting.

Version 2.0.0.2
Copy link

Software released: June 4, 2026 | Release notes published: July 14, 2026

Improved:

  • Removed DPDK as a dependency and replaced it with custom thread-management and memory allocations, resulting in a 7.6% packet capture performance improvement.

  • Raised thread limit from 16 to 32, resulting in better performance on 100 Gbps sensors with sufficient hardware.

  • This release includes improvements to event throughput.

Fixed:

  • Fixed a bug where multicast flows would sometimes be assigned the wrong direction.
  • Fixed protocol detection accuracy for STUN and mDNS.

New Protocols:

  • WUDO: The sensor now detects the Windows Update Delivery Optimization (WUDO) protocol, which is used by Windows endpoints to share update content peer-to-peer across a local network.
  • Cohesity RPC protocol: The sensor now detects the Cohesity Remote Procedure Call (RPC) protocol, used by the Cohesity Data Protection and Security Platform.
  • Aerohive Mobility Routing protocol: The sensor now detects the Aerohive Mobility Routing protocol, used by Aerohive wireless infrastructure for access point coordination.

Top of page